nblm

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The core Google NotebookLM automation is mostly aligned with the stated purpose, and data largely flows to official Google properties rather than an unrelated proxy. However, automatic dependency installation without visible verification, persistent auth storage, broad file/URL ingestion, browser automation, and the added Z-Library integration make the footprint larger and riskier than a simple query skill.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/magicseek%2Fnblm%2Fnblm%2F@6d989d4b17be50fb3f0fb744d26032173fc01a2d
Security Audit — socket — nblm